PkgRadar

Go modules · proxy.golang.org

github.com/faramesh/faramesh-core

Remote Payload: matched "curl "

Why PkgRadar flagged v1.2.10-0.20260526042839-f0a690713cd8

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · github.com/faramesh/[email protected]/cmd/faramesh/update_uninstall.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/faramesh/[email protected]/internal/registry/github.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.2.10-0.20260526042839-f0a690713cd8Review442026-05-30
v0.2.9Review322026-05-30
v0.2.5Review322026-05-30
v0.2.7Review322026-05-30
v0.5.0Review202026-05-30
v0.2.0Review442026-05-30
v0.2.6Review322026-05-30
v0.2.3Review202026-05-30
v0.4.0Review202026-05-30
v0.9.0Review322026-05-30
v0.6.0Review202026-05-30

Block this in CI

PkgRadar gates github.com/faramesh/faramesh-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/faramesh/[email protected]